Finst

Blockstream Introduces SHRINCS as a Quantum-Safe Bitcoin Fix

The proposal is meant to better shield Bitcoin from future quantum attacks, with less block space loss than many existing post-quantum schemes. The debate also touches on SegWit, SHA-256, and a possible soft fork.

Blockstream Introduces SHRINCS as a Quantum-Safe Bitcoin Fix

Key Takeaways

  • Blockstream has proposed SHRINCS as a quantum-safe signature for Bitcoin, with less capacity loss than many existing post-quantum designs.
  • According to the researchers, SHRINCS can bring throughput down to about three transactions per second, compared with around 0.36 for SLH-DSA.
  • The proposal is still at an early stage: the security proof and formal audit of the reference software are not finished yet.

Blockstream has published a proposal for SHRINCS, a way to sign Bitcoin transactions that is meant to withstand quantum computers without sharply cutting into block capacity. The researchers say the system leaves more transaction space than many existing post-quantum designs, while still adding an extra layer of defense for Bitcoin.

Why Bitcoin Is Vulnerable

Bitcoin uses digital signatures based on elliptic curve cryptography to prove ownership. That lets a user show they control the private key without revealing the key itself.

The risk lies in a future quantum computer powerful enough to break that protection with Shor's algorithm. In theory, such a machine could work backward from a public key on the blockchain to the private key, after which an attacker could forge a signature and move coins.

That makes old addresses especially relevant, because their public keys have already been exposed. According to the researchers, a lot of Bitcoin is still sitting on those addresses, including more than 1.1 million BTC attributed to Satoshi Nakamoto.

SHRINCS Is Meant to Save Space

The biggest problem with post-quantum signatures is their size. NIST standards are often many times larger than the signatures Bitcoin uses today, which means fewer transactions fit in a block.

Blockstream estimates that Bitcoin can process about 6.5 transactions per second with its current compact Schnorr signatures. With SLH-DSA, that would drop to about 0.36 transactions per second. According to the researchers, SHRINCS brings that back up to about three transactions per second, with signatures starting at around 324 bytes and growing to about 580 bytes.

SegWit, the 2017 upgrade that gives the signature part of a transaction a discount, also helps. SHRINCS also uses SHA-256, the same hash function already widely used in Bitcoin, so the system does not rely on a completely new mathematical foundation.

Jonas Nick, who designed SHRINCS together with Blockstream researcher Mikhail Kudinov, calls it the first concrete post-quantum signature made specifically for Bitcoin. At the same time, he says it is not meant to be the final solution and not the best option in every case.

What This Means for Bitcoin

For European crypto readers, this matters because it shows the quantum-security debate is no longer theoretical. A recent Google analysis suggests quantum computers may be able to break elliptic curve cryptography as early as 2029, while another study points to a lower number of required qubits than previously thought.

That makes the question of how Bitcoin can adapt in time more concrete. For a network that relies on broad consensus, a soft fork would be needed to make such a change, and that step still needs enough support from the community.

Blockstream previously showed SHRINCS on Liquid, a separate blockchain the company runs for faster and more private transfers of Bitcoin and other assets. For Bitcoin itself, the proposal is still at the beginning: the formal security proof is not finished yet and the reference software has not been formally audited yet.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.